Is EMP.dll a malware ? Hogwarts Legacy crack from Empress

Is EMP.dll a malware ? Hogwarts Legacy crack from Empress

Hello, I have been wondering why is the file EMP.dll flagged as a virus in the last crack of Empress (https://www.virustotal.com/gui/file/0113bddb8c8fe0f2efcd447fe491ed1b61bfa32e17e460c170b8ac959636f2f9) and every one online is just saying to disable your antivirus without any explanation. A scan of the file clearly shows that it’s using obfuscation and unusual techniques https://www.filescan.io/reports/0113bddb8c8fe0f2efcd447fe491ed1b61bfa32e17e460c170b8ac959636f2f9/16e45304-88d7-4051-ab8c-eaafeabe8be8/overview

So I tried to see for myself what happens when you execute that code but I don’t have experience in reverse engineering of malwares and I need help. So far, using sysinternals tools, I could see that the code tries to open a powershell and an openSSH client, that looks like a red flag to me but

Logs \”rundll32 EMP.dll PE\”

I want to be sure.

Can someone help me to analyze this further with some direction to follow ? Am I even interpreting the logs right ?

submitted by /u/MyUsernameIsBizon
[link] [comments]

March 5, 2023
Read More >>